Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,202
Critical1,003
High3,353
Medium11,595
Reset
Showing 12401-12420 of 16202 records
Threat Entry Updated 2024-11-21

CVE-2023-49825 - Soledad Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme.This issue affects Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme: from n/a through 8.4.1.

PLUGIN Soledad

CVE-2023-49825

HIGH CVSS 8.5 2023-12-20
Threat Entry Updated 2024-11-21

CVE-2023-47236 - Ipages Flipbook Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Avirtum iPages Flipbook For WordPress.This issue affects iPages Flipbook For WordPress: from n/a through 1.4.8.

PLUGIN Ipages Flipbook

CVE-2023-47236

HIGH CVSS 7.6 2023-12-20
Threat Entry Updated 2024-11-21

CVE-2023-38519 - Mainwp Dashboard Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MainWP MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance.This issue affects MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance: from n/a through 4.4.3.3.

PLUGIN Mainwp Dashboard

CVE-2023-38519

HIGH CVSS 7.6 2023-12-20
Threat Entry Updated 2024-11-21

CVE-2023-49750 - Couponis Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spoonthemes Couponis - Affiliate & Submitting Coupons WordPress Theme.This issue affects Couponis - Affiliate & Submitting Coupons WordPress Theme: from n/a before 2.2.

PLUGIN Couponis

CVE-2023-49750

CRITICAL CVSS 9.3 2023-12-19
Threat Entry Updated 2024-11-21

CVE-2023-48764 - Guardgiant Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GuardGiant Brute Force Protection WordPress Brute Force Protection – Stop Brute Force Attacks.This issue affects WordPress Brute Force Protection – Stop Brute Force Attacks: from n/a through 2.2.5.

PLUGIN Guardgiant

CVE-2023-48764

HIGH CVSS 7.6 2023-12-19
Threat Entry Updated 2024-11-21

CVE-2023-45105 - Affiliate Toolkit Plugin

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SERVIT Software Solutions affiliate-toolkit – WordPress Affiliate Plugin.This issue affects affiliate-toolkit – WordPress Affiliate Plugin: from n/a through 3.3.9.

PLUGIN Affiliate Toolkit

CVE-2023-45105

MEDIUM CVSS 4.7 2023-12-19
Threat Entry Updated 2024-11-21

CVE-2023-25715 - Gamipress Plugin

Missing Authorization vulnerability in GamiPress GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress.This issue affects GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress: from n/a through 2.5.6.

PLUGIN Gamipress

CVE-2023-25715

MEDIUM CVSS 5.4 2023-12-19
Threat Entry Updated 2024-11-21

CVE-2023-5432 - Jquery News Ticker Plugin

The Jquery news ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'jquery-news-ticker' shortcode in versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Jquery News Ticker

CVE-2023-5432

MEDIUM CVSS 6.4 2023-12-19
Threat Entry Updated 2024-11-21

CVE-2023-5413 - Image Horizontal Reel Scroll Slideshow Plugin

The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'ihrss-gallery' shortcode in versions up to, and including, 13.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Image Horizontal Reel Scroll Slideshow

CVE-2023-5413

MEDIUM CVSS 6.4 2023-12-19
Threat Entry Updated 2024-11-21

CVE-2023-6488 - Shortcodes Ultimate Plugin

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_button', 'su_members', and 'su_tabs' shortcodes in all versions up to, and including, 7.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Shortcodes Ultimate

CVE-2023-6488

MEDIUM CVSS 5.4 2023-12-19
Threat Entry Updated 2024-11-21

CVE-2023-46154 - E2pdf Plugin

Deserialization of Untrusted Data vulnerability in E2Pdf.Com E2Pdf – Export To Pdf Tool for WordPress.This issue affects E2Pdf – Export To Pdf Tool for WordPress: from n/a through 1.20.18.

PLUGIN E2pdf

CVE-2023-46154

MEDIUM CVSS 6.6 2023-12-19
Threat Entry Updated 2024-11-21

CVE-2023-49821 - Wp Live Chat Plugin

Cross-Site Request Forgery (CSRF) vulnerability in LiveChat LiveChat – WP live chat plugin for WordPress.This issue affects LiveChat – WP live chat plugin for WordPress: from n/a through 4.5.15.

PLUGIN Wp Live Chat

CVE-2023-49821

MEDIUM CVSS 5.4 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-6295 - Siteorigin Widgets Bundle Plugin

The SiteOrigin Widgets Bundle WordPress plugin before 1.51.0 does not validate user input before using it to generate paths passed to include function/s, allowing users with the administrator role to perform LFI attacks in the context of Multisite WordPress sites.

PLUGIN Siteorigin Widgets Bundle

CVE-2023-6295

HIGH CVSS 7.2 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-6272 - Theme My Login 2fa Plugin

The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attacker to brute-force all possibilities, which shouldn't be too long, as the 2FA codes are 6 digits.

PLUGIN Theme My Login 2fa

CVE-2023-6272

CRITICAL CVSS 9.8 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-5886 - Wp All Export Pro Plugin

The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers with the ability to upload files to make logged in users perform unwanted actions leading to PHAR deserialization, which may lead to remote code execution.

PLUGIN Wp All Export Pro

CVE-2023-5886

HIGH CVSS 8.8 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-5882 - Wp All Export Pro Plugin

The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers to make logged in users perform unwanted actions leading to remote code execution.

PLUGIN Wp All Export Pro

CVE-2023-5882

HIGH CVSS 8.8 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-4311 - Vrm360 Plugin

The Vrm 360 3D Model Viewer WordPress plugin through 1.2.1 is vulnerable to arbitrary file upload due to insufficient checks in a plugin shortcode.

PLUGIN Vrm360

CVE-2023-4311

HIGH CVSS 8.8 2023-12-18
Scroll to top